You are viewing documentation for version 3 of the AWS SDK for Ruby. Version 2 documentation can be found here.

Class: Aws::Shield::Client

Inherits:
Seahorse::Client::Base show all
Includes:
ClientStubs
Defined in:
gems/aws-sdk-shield/lib/aws-sdk-shield/client.rb

Instance Attribute Summary

Attributes inherited from Seahorse::Client::Base

#config, #handlers

API Operations collapse

Instance Method Summary collapse

Methods included from ClientStubs

#stub_data, #stub_responses

Methods inherited from Seahorse::Client::Base

add_plugin, api, clear_plugins, define, new, #operation_names, plugins, remove_plugin, set_api, set_plugins

Methods included from Seahorse::Client::HandlerBuilder

#handle, #handle_request, #handle_response

Constructor Details

#initialize(*args) ⇒ Client

Returns a new instance of Client

Parameters:

  • options (Hash)

    a customizable set of options



163
164
165
# File 'gems/aws-sdk-shield/lib/aws-sdk-shield/client.rb', line 163

def initialize(*args)
  super
end

Instance Method Details

#associate_drt_log_bucket(params = {}) ⇒ Struct

Authorizes the DDoS Response team (DRT) to access the specified Amazon S3 bucket containing your flow logs. You can associate up to 10 Amazon S3 buckets with your subscription.

To use the services of the DRT and make an AssociateDRTLogBucket request, you must be subscribed to the Business Support plan or the Enterprise Support plan.

Examples:

Request syntax with placeholder values


resp = client.associate_drt_log_bucket({
  log_bucket: "LogBucket", # required
})

Parameters:

  • params (Hash) (defaults to: {})

    ({})

Options Hash (params):

  • :log_bucket (required, String)

    The Amazon S3 bucket that contains your flow logs.

Returns:

  • (Struct)

    Returns an empty response.

See Also:



197
198
199
200
# File 'gems/aws-sdk-shield/lib/aws-sdk-shield/client.rb', line 197

def associate_drt_log_bucket(params = {}, options = {})
  req = build_request(:associate_drt_log_bucket, params)
  req.send_request(options)
end

#associate_drt_role(params = {}) ⇒ Struct

Authorizes the DDoS Response team (DRT), using the specified role, to access your AWS account to assist with DDoS attack mitigation during potential attacks. This enables the DRT to inspect your AWS WAF configuration and create or update AWS WAF rules and web ACLs.

You can associate only one RoleArn with your subscription. If you submit an AssociateDRTRole request for an account that already has an associated role, the new RoleArn will replace the existing RoleArn.

Prior to making the AssociateDRTRole request, you must attach the AWSShieldDRTAccessPolicy managed policy to the role you will specify in the request. For more information see Attaching and Detaching IAM Policies. The role must also trust the service principal drt.shield.amazonaws.com. For more information, see IAM JSON Policy Elements: Principal.

The DRT will have access only to your AWS WAF and Shield resources. By submitting this request, you authorize the DRT to inspect your AWS WAF and Shield configuration and create and update AWS WAF rules and web ACLs on your behalf. The DRT takes these actions only if explicitly authorized by you.

You must have the iam:PassRole permission to make an AssociateDRTRole request. For more information, see Granting a User Permissions to Pass a Role to an AWS Service.

To use the services of the DRT and make an AssociateDRTRole request, you must be subscribed to the Business Support plan or the Enterprise Support plan.

Examples:

Request syntax with placeholder values


resp = client.associate_drt_role({
  role_arn: "RoleArn", # required
})

Parameters:

  • params (Hash) (defaults to: {})

    ({})

Options Hash (params):

  • :role_arn (required, String)

    The Amazon Resource Name (ARN) of the role the DRT will use to access your AWS account.

    Prior to making the AssociateDRTRole request, you must attach the AWSShieldDRTAccessPolicy managed policy to this role. For more information see Attaching and Detaching IAM Policies.

Returns:

  • (Struct)

    Returns an empty response.

See Also:



268
269
270
271
# File 'gems/aws-sdk-shield/lib/aws-sdk-shield/client.rb', line 268

def associate_drt_role(params = {}, options = {})
  req = build_request(:associate_drt_role, params)
  req.send_request(options)
end

#create_protection(params = {}) ⇒ Types::CreateProtectionResponse

Enables AWS Shield Advanced for a specific AWS resource. The resource can be an Amazon CloudFront distribution, Elastic Load Balancing load balancer, Elastic IP Address, or an Amazon Route 53 hosted zone.

You can add protection to only a single resource with each CreateProtection request. If you want to add protection to multiple resources at once, use the AWS WAF console. For more information see Getting Started with AWS Shield Advanced and Add AWS Shield Advanced Protection to more AWS Resources.

Examples:

Request syntax with placeholder values


resp = client.create_protection({
  name: "ProtectionName", # required
  resource_arn: "ResourceArn", # required
})

Response structure


resp.protection_id #=> String

Parameters:

  • params (Hash) (defaults to: {})

    ({})

Options Hash (params):

  • :name (required, String)

    Friendly name for the Protection you are creating.

  • :resource_arn (required, String)

    The ARN (Amazon Resource Name) of the resource to be protected.

    The ARN should be in one of the following formats:

    • For an Application Load Balancer: arn:aws:elasticloadbalancing:region:account-id:loadbalancer/app/load-balancer-name/load-balancer-id

    • For an Elastic Load Balancer (Classic Load Balancer): arn:aws:elasticloadbalancing:region:account-id:loadbalancer/load-balancer-name

    • For AWS CloudFront distribution: arn:aws:cloudfront::account-id:distribution/distribution-id

    • For Amazon Route 53: arn:aws:route53::account-id:hostedzone/hosted-zone-id

    • For an Elastic IP address: arn:aws:ec2:region:account-id:eip-allocation/allocation-id

Returns:

See Also:



333
334
335
336
# File 'gems/aws-sdk-shield/lib/aws-sdk-shield/client.rb', line 333

def create_protection(params = {}, options = {})
  req = build_request(:create_protection, params)
  req.send_request(options)
end

#create_subscription(params = {}) ⇒ Struct

Activates AWS Shield Advanced for an account.

As part of this request you can specify EmergencySettings that automaticaly grant the DDoS response team (DRT) needed permissions to assist you during a suspected DDoS attack. For more information see Authorize the DDoS Response Team to Create Rules and Web ACLs on Your Behalf.

When you initally create a subscription, your subscription is set to be automatically renewed at the end of the existing subscription period. You can change this by submitting an UpdateSubscription request.

Parameters:

  • params (Hash) (defaults to: {})

    ({})

Returns:

  • (Struct)

    Returns an empty response.

See Also:



361
362
363
364
# File 'gems/aws-sdk-shield/lib/aws-sdk-shield/client.rb', line 361

def create_subscription(params = {}, options = {})
  req = build_request(:create_subscription, params)
  req.send_request(options)
end

#delete_protection(params = {}) ⇒ Struct

Deletes an AWS Shield Advanced Protection.

Examples:

Request syntax with placeholder values


resp = client.delete_protection({
  protection_id: "ProtectionId", # required
})

Parameters:

  • params (Hash) (defaults to: {})

    ({})

Options Hash (params):

  • :protection_id (required, String)

    The unique identifier (ID) for the Protection object to be deleted.

Returns:

  • (Struct)

    Returns an empty response.

See Also:



383
384
385
386
# File 'gems/aws-sdk-shield/lib/aws-sdk-shield/client.rb', line 383

def delete_protection(params = {}, options = {})
  req = build_request(:delete_protection, params)
  req.send_request(options)
end

#delete_subscription(params = {}) ⇒ Struct

Removes AWS Shield Advanced from an account. AWS Shield Advanced requires a 1-year subscription commitment. You cannot delete a subscription prior to the completion of that commitment.

Parameters:

  • params (Hash) (defaults to: {})

    ({})

Returns:

  • (Struct)

    Returns an empty response.

See Also:



398
399
400
401
# File 'gems/aws-sdk-shield/lib/aws-sdk-shield/client.rb', line 398

def delete_subscription(params = {}, options = {})
  req = build_request(:delete_subscription, params)
  req.send_request(options)
end

#describe_attack(params = {}) ⇒ Types::DescribeAttackResponse

Describes the details of a DDoS attack.

Examples:

Request syntax with placeholder values


resp = client.describe_attack({
  attack_id: "AttackId", # required
})

Response structure


resp.attack.attack_id #=> String
resp.attack.resource_arn #=> String
resp.attack.sub_resources #=> Array
resp.attack.sub_resources[0].type #=> String, one of "IP", "URL"
resp.attack.sub_resources[0].id #=> String
resp.attack.sub_resources[0].attack_vectors #=> Array
resp.attack.sub_resources[0].attack_vectors[0].vector_type #=> String
resp.attack.sub_resources[0].attack_vectors[0].vector_counters #=> Array
resp.attack.sub_resources[0].attack_vectors[0].vector_counters[0].name #=> String
resp.attack.sub_resources[0].attack_vectors[0].vector_counters[0].max #=> Float
resp.attack.sub_resources[0].attack_vectors[0].vector_counters[0].average #=> Float
resp.attack.sub_resources[0].attack_vectors[0].vector_counters[0].sum #=> Float
resp.attack.sub_resources[0].attack_vectors[0].vector_counters[0].n #=> Integer
resp.attack.sub_resources[0].attack_vectors[0].vector_counters[0].unit #=> String
resp.attack.sub_resources[0].counters #=> Array
resp.attack.sub_resources[0].counters[0].name #=> String
resp.attack.sub_resources[0].counters[0].max #=> Float
resp.attack.sub_resources[0].counters[0].average #=> Float
resp.attack.sub_resources[0].counters[0].sum #=> Float
resp.attack.sub_resources[0].counters[0].n #=> Integer
resp.attack.sub_resources[0].counters[0].unit #=> String
resp.attack.start_time #=> Time
resp.attack.end_time #=> Time
resp.attack.attack_counters #=> Array
resp.attack.attack_counters[0].name #=> String
resp.attack.attack_counters[0].max #=> Float
resp.attack.attack_counters[0].average #=> Float
resp.attack.attack_counters[0].sum #=> Float
resp.attack.attack_counters[0].n #=> Integer
resp.attack.attack_counters[0].unit #=> String
resp.attack.attack_properties #=> Array
resp.attack.attack_properties[0].attack_layer #=> String, one of "NETWORK", "APPLICATION"
resp.attack.attack_properties[0].attack_property_identifier #=> String, one of "DESTINATION_URL", "REFERRER", "SOURCE_ASN", "SOURCE_COUNTRY", "SOURCE_IP_ADDRESS", "SOURCE_USER_AGENT"
resp.attack.attack_properties[0].top_contributors #=> Array
resp.attack.attack_properties[0].top_contributors[0].name #=> String
resp.attack.attack_properties[0].top_contributors[0].value #=> Integer
resp.attack.attack_properties[0].unit #=> String, one of "BITS", "BYTES", "PACKETS", "REQUESTS"
resp.attack.attack_properties[0].total #=> Integer
resp.attack.mitigations #=> Array
resp.attack.mitigations[0].mitigation_name #=> String

Parameters:

  • params (Hash) (defaults to: {})

    ({})

Options Hash (params):

  • :attack_id (required, String)

    The unique identifier (ID) for the attack that to be described.

Returns:

See Also:



465
466
467
468
# File 'gems/aws-sdk-shield/lib/aws-sdk-shield/client.rb', line 465

def describe_attack(params = {}, options = {})
  req = build_request(:describe_attack, params)
  req.send_request(options)
end

#describe_drt_access(params = {}) ⇒ Types::DescribeDRTAccessResponse

Returns the current role and list of Amazon S3 log buckets used by the DDoS Response team (DRT) to access your AWS account while assisting with attack mitigation.

Examples:

Response structure


resp.role_arn #=> String
resp.log_bucket_list #=> Array
resp.log_bucket_list[0] #=> String

Parameters:

  • params (Hash) (defaults to: {})

    ({})

Returns:

See Also:



489
490
491
492
# File 'gems/aws-sdk-shield/lib/aws-sdk-shield/client.rb', line 489

def describe_drt_access(params = {}, options = {})
  req = build_request(:describe_drt_access, params)
  req.send_request(options)
end

#describe_emergency_contact_settings(params = {}) ⇒ Types::DescribeEmergencyContactSettingsResponse

Lists the email addresses that the DRT can use to contact you during a suspected attack.

Examples:

Response structure


resp.emergency_contact_list #=> Array
resp.emergency_contact_list[0].email_address #=> String

Parameters:

  • params (Hash) (defaults to: {})

    ({})

Returns:

See Also:



510
511
512
513
# File 'gems/aws-sdk-shield/lib/aws-sdk-shield/client.rb', line 510

def describe_emergency_contact_settings(params = {}, options = {})
  req = build_request(:describe_emergency_contact_settings, params)
  req.send_request(options)
end

#describe_protection(params = {}) ⇒ Types::DescribeProtectionResponse

Lists the details of a Protection object.

Examples:

Request syntax with placeholder values


resp = client.describe_protection({
  protection_id: "ProtectionId", # required
})

Response structure


resp.protection.id #=> String
resp.protection.name #=> String
resp.protection.resource_arn #=> String

Parameters:

  • params (Hash) (defaults to: {})

    ({})

Options Hash (params):

  • :protection_id (required, String)

    The unique identifier (ID) for the Protection object that is described.

Returns:

See Also:



541
542
543
544
# File 'gems/aws-sdk-shield/lib/aws-sdk-shield/client.rb', line 541

def describe_protection(params = {}, options = {})
  req = build_request(:describe_protection, params)
  req.send_request(options)
end

#describe_subscription(params = {}) ⇒ Types::DescribeSubscriptionResponse

Provides details about the AWS Shield Advanced subscription for an account.

Examples:

Response structure


resp.subscription.start_time #=> Time
resp.subscription.end_time #=> Time
resp.subscription.time_commitment_in_seconds #=> Integer
resp.subscription.auto_renew #=> String, one of "ENABLED", "DISABLED"
resp.subscription.limits #=> Array
resp.subscription.limits[0].type #=> String
resp.subscription.limits[0].max #=> Integer

Parameters:

  • params (Hash) (defaults to: {})

    ({})

Returns:

See Also:



567
568
569
570
# File 'gems/aws-sdk-shield/lib/aws-sdk-shield/client.rb', line 567

def describe_subscription(params = {}, options = {})
  req = build_request(:describe_subscription, params)
  req.send_request(options)
end

#disassociate_drt_log_bucket(params = {}) ⇒ Struct

Removes the DDoS Response team's (DRT) access to the specified Amazon S3 bucket containing your flow logs.

To make a DisassociateDRTLogBucket request, you must be subscribed to the Business Support plan or the Enterprise Support plan. However, if you are not subscribed to one of these support plans, but had been previously and had granted the DRT access to your account, you can submit a DisassociateDRTLogBucket request to remove this access.

Examples:

Request syntax with placeholder values


resp = client.disassociate_drt_log_bucket({
  log_bucket: "LogBucket", # required
})

Parameters:

  • params (Hash) (defaults to: {})

    ({})

Options Hash (params):

  • :log_bucket (required, String)

    The Amazon S3 bucket that contains your flow logs.

Returns:

  • (Struct)

    Returns an empty response.

See Also:



602
603
604
605
# File 'gems/aws-sdk-shield/lib/aws-sdk-shield/client.rb', line 602

def disassociate_drt_log_bucket(params = {}, options = {})
  req = build_request(:disassociate_drt_log_bucket, params)
  req.send_request(options)
end

#disassociate_drt_role(params = {}) ⇒ Struct

Removes the DDoS Response team's (DRT) access to your AWS account.

To make a DisassociateDRTRole request, you must be subscribed to the Business Support plan or the Enterprise Support plan. However, if you are not subscribed to one of these support plans, but had been previously and had granted the DRT access to your account, you can submit a DisassociateDRTRole request to remove this access.

Parameters:

  • params (Hash) (defaults to: {})

    ({})

Returns:

  • (Struct)

    Returns an empty response.

See Also:



626
627
628
629
# File 'gems/aws-sdk-shield/lib/aws-sdk-shield/client.rb', line 626

def disassociate_drt_role(params = {}, options = {})
  req = build_request(:disassociate_drt_role, params)
  req.send_request(options)
end

#get_subscription_state(params = {}) ⇒ Types::GetSubscriptionStateResponse

Returns the SubscriptionState, either Active or Inactive.

Examples:

Response structure


resp.subscription_state #=> String, one of "ACTIVE", "INACTIVE"

Parameters:

  • params (Hash) (defaults to: {})

    ({})

Returns:

See Also:



645
646
647
648
# File 'gems/aws-sdk-shield/lib/aws-sdk-shield/client.rb', line 645

def get_subscription_state(params = {}, options = {})
  req = build_request(:get_subscription_state, params)
  req.send_request(options)
end

#list_attacks(params = {}) ⇒ Types::ListAttacksResponse

Returns all ongoing DDoS attacks or all DDoS attacks during a specified time period.

Examples:

Request syntax with placeholder values


resp = client.list_attacks({
  resource_arns: ["ResourceArn"],
  start_time: {
    from_inclusive: Time.now,
    to_exclusive: Time.now,
  },
  end_time: {
    from_inclusive: Time.now,
    to_exclusive: Time.now,
  },
  next_token: "Token",
  max_results: 1,
})

Response structure


resp.attack_summaries #=> Array
resp.attack_summaries[0].attack_id #=> String
resp.attack_summaries[0].resource_arn #=> String
resp.attack_summaries[0].start_time #=> Time
resp.attack_summaries[0].end_time #=> Time
resp.attack_summaries[0].attack_vectors #=> Array
resp.attack_summaries[0].attack_vectors[0].vector_type #=> String
resp.next_token #=> String

Parameters:

  • params (Hash) (defaults to: {})

    ({})

Options Hash (params):

  • :resource_arns (Array<String>)

    The ARN (Amazon Resource Name) of the resource that was attacked. If this is left blank, all applicable resources for this account will be included.

  • :start_time (Types::TimeRange)

    The start of the time period for the attacks. This is a timestamp type. The sample request above indicates a number type because the default used by WAF is Unix time in seconds. However any valid timestamp format is allowed.

  • :end_time (Types::TimeRange)

    The end of the time period for the attacks. This is a timestamp type. The sample request above indicates a number type because the default used by WAF is Unix time in seconds. However any valid timestamp format is allowed.

  • :next_token (String)

    The ListAttacksRequest.NextMarker value from a previous call to ListAttacksRequest. Pass null if this is the first call.

  • :max_results (Integer)

    The maximum number of AttackSummary objects to be returned. If this is left blank, the first 20 results will be returned.

Returns:

See Also:



722
723
724
725
# File 'gems/aws-sdk-shield/lib/aws-sdk-shield/client.rb', line 722

def list_attacks(params = {}, options = {})
  req = build_request(:list_attacks, params)
  req.send_request(options)
end

#list_protections(params = {}) ⇒ Types::ListProtectionsResponse

Lists all Protection objects for the account.

Examples:

Request syntax with placeholder values


resp = client.list_protections({
  next_token: "Token",
  max_results: 1,
})

Response structure


resp.protections #=> Array
resp.protections[0].id #=> String
resp.protections[0].name #=> String
resp.protections[0].resource_arn #=> String
resp.next_token #=> String

Parameters:

  • params (Hash) (defaults to: {})

    ({})

Options Hash (params):

  • :next_token (String)

    The ListProtectionsRequest.NextToken value from a previous call to ListProtections. Pass null if this is the first call.

  • :max_results (Integer)

    The maximum number of Protection objects to be returned. If this is left blank the first 20 results will be returned.

Returns:

See Also:



761
762
763
764
# File 'gems/aws-sdk-shield/lib/aws-sdk-shield/client.rb', line 761

def list_protections(params = {}, options = {})
  req = build_request(:list_protections, params)
  req.send_request(options)
end

#update_emergency_contact_settings(params = {}) ⇒ Struct

Updates the details of the list of email addresses that the DRT can use to contact you during a suspected attack.

Examples:

Request syntax with placeholder values


resp = client.update_emergency_contact_settings({
  emergency_contact_list: [
    {
      email_address: "EmailAddress", # required
    },
  ],
})

Parameters:

  • params (Hash) (defaults to: {})

    ({})

Options Hash (params):

  • :emergency_contact_list (Array<Types::EmergencyContact>)

    A list of email addresses that the DRT can use to contact you during a suspected attack.

Returns:

  • (Struct)

    Returns an empty response.

See Also:



789
790
791
792
# File 'gems/aws-sdk-shield/lib/aws-sdk-shield/client.rb', line 789

def update_emergency_contact_settings(params = {}, options = {})
  req = build_request(:update_emergency_contact_settings, params)
  req.send_request(options)
end

#update_subscription(params = {}) ⇒ Struct

Updates the details of an existing subscription. Only enter values for parameters you want to change. Empty parameters are not updated.

Examples:

Request syntax with placeholder values


resp = client.update_subscription({
  auto_renew: "ENABLED", # accepts ENABLED, DISABLED
})

Parameters:

  • params (Hash) (defaults to: {})

    ({})

Options Hash (params):

  • :auto_renew (String)

    When you initally create a subscription, AutoRenew is set to ENABLED. If ENABLED, the subscription will be automatically renewed at the end of the existing subscription period. You can change this by submitting an UpdateSubscription request. If the UpdateSubscription request does not included a value for AutoRenew, the existing value for AutoRenew remains unchanged.

Returns:

  • (Struct)

    Returns an empty response.

See Also:



817
818
819
820
# File 'gems/aws-sdk-shield/lib/aws-sdk-shield/client.rb', line 817

def update_subscription(params = {}, options = {})
  req = build_request(:update_subscription, params)
  req.send_request(options)
end